Privacy Policy

Effective: April 2025 · Last reviewed: July 2026

UniPass is a local-first, zero-knowledge password manager. By design we do everything we can to minimize the data we can see — because data we can see is data that can leak.

In short

What we collect

Without cloud sync (local mode)

No account or vault data is sent to UniPass. Your master password, vault contents, Secret Key, and device identifiers stay on your device. The desktop app can still make the favicon and user-initiated breach-check requests described below; those services receive your network IP as part of an ordinary HTTPS connection.

With cloud sync enabled

Only the following is uploaded to our sync server:

CategoryUploaded?Notes
Master passwordNoNever leaves the device; the server only sees an Argon2id-derived auth hash (irreversible).
Vault records (logins, notes, cards, etc.)Ciphertext onlyOpaque XChaCha20-Poly1305 blobs; the server has no key to decrypt them.
Secret KeyNoGenerated at sign-up, stored in the device Keychain, and never sent in plaintext.
Recovery CodeNoThe code is displayed once and never uploaded. If you enable recovery, the server stores only an encrypted recovery envelope and a one-way verifier.
Sync metadataYesAccount email, device name/type, sync timestamps, record version numbers.
Usage analytics / telemetryNoNo analytics SDKs integrated (no Sentry / Firebase / GA / Mixpanel).
Crash reportsNoNo crash reporting integrated.
Client IPTransientKept only in web access logs as operationally needed; not written to the user database.
FaviconsSee belowThe stored domain can be sent to the target site and, on fallback, Google's Favicon service. No username, password, note, or other vault field is sent.
Password breach checkSee belowOnly when you run the check, the first five characters of each password's SHA-1 hash are sent to Have I Been Pwned's range API. Plaintext passwords and full hashes are not sent.

We never upload your master password or any derived key, plaintext vault content, or your browser history, clipboard, or filenames.

Enabling cloud sync is an explicit action — you must enter a server URL and confirm under Settings → Cloud Sync in the desktop app.

The browser extension

The UniPass browser extension for Microsoft Edge and other supported Chromium-based browsers is a companion to the desktop app. It detects login forms, fills credentials in response to user actions, and handles submitted login values only to offer a local save or update prompt. Credentials travel only between the extension and the local desktop app through your operating system's Native Messaging channel — never over the network to us. The extension contains no analytics and sends no browsing data anywhere.

Third-party services

UniPass does not use third-party advertising or analytics services.

Where data is stored

All local data lives in the standard OS user-data directory:

The database is encrypted with SQLCipher using a key derived from your master password. OS file permissions (0600) prevent other users from reading it.

Data deletion

Children's privacy

UniPass is not directed to children under 13 and does not knowingly collect personal data from minors.

Changes

Revisions to this policy are announced in the project's release notes. Material changes will be communicated to users in advance.

Contact

Operator and proposed billing data processing

UniPass is operated by 上海洛克斯网络科技有限公司. Privacy contact: business@loxnet.io.

Commercial subscriptions are not enabled. At launch, Paddle is planned to process checkout and payment details. UniPass would receive customer, order and subscription identifiers, billing email, plan, payment status and renewal dates needed to link an account, deliver benefits, support customers, handle refunds and maintain billing records. UniPass would not receive full card numbers or card security codes, or send vault contents to the payment provider.

The exact billing fields, cross-border processing arrangements and statutory retention periods will be published after integration validation and before charging begins. See Paddle’s privacy policy for its processing. This section describes proposed processing, not current billing activity.